Thursday, 8 October 2026

Budget Android phones arrive with firmware malware that runs apps

Security researchers uncover a firmware threat on budget Android phones that can silently install apps, commit ad fraud, and relay traffic through owners’ networks.

Close-up of a generic budget Android phone on a desk

The short version

  • Researchers warn about a firmware-level malware campaign on budget Android phones that cannot be removed with normal uninstalls.
  • The malware, called Midnight Mimosa, can install or delete apps and download more components from remote servers with system privileges.
  • Victims span over 150 countries, involving models that mimic popular brands and several well-known low-cost devices.
  • Some infected phones are used as residential proxies to relay traffic and generate advertising revenue without user action.
Quick read · 2 min

A new threat named Midnight Mimosa has been found preinstalled on budget Android phones. It’s embedded in the firmware, letting attackers install or delete apps and fetch more code from remote servers, all without user action. The issue spans thousands of devices in over 150 countries and includes models that mimic popular brands.

The malware also turns infected phones into residential proxies to relay traffic for others, potentially supporting ad fraud. Some devices reappear with infections after cleanup, suggesting a persistent risk in affected firmware. The precise source and timing of the tampering remain unclear.

For everyday users, the takeaways are to be cautious with budget devices, monitor data usage, and only apply firmware updates from trusted channels. If you notice odd behavior, a factory reset or clean firmware flash is a common remedy, though results vary by device. More protections around firmware integrity are likely to come from manufacturers and regulators.

A new threat is surfacing in the budget Android market: malware embedded directly in the device firmware. Researchers have dubbed the campaign Midnight Mimosa, and it lives in the system partition, giving attackers high-level access that lets them install or remove apps and fetch additional modules without any user interaction. The spread has touched thousands of devices in more than 150 countries over about two years.

Bitdefender researchers traced the malware to a family of preinstalled system components that masquerade as legitimate Android packages. The core module, named by investigators as com.android.system.lite, can quietly manage other apps and pull in extra code from command-and-control servers, expanding its reach without requiring user downloads.

Beyond stealthy app management, the malware can also turn infected devices into residential proxies. That means the phone can relay other people’s online traffic through the owner’s network, potentially backing ad fraud or other illicit activity. A second component, disguised as ordinary utilities like weather apps or file managers, handles the proxy tasks and talks to a remote server for fresh instructions.

The campaign’s footprint is broad. Security researchers say victims exist across more than 150 countries, with affected devices including models that imitate familiar brands. Some owners have reported that apps reappear after being removed, hinting that the malware can recover itself after user cleanup. In some instances, firmware updates from manufacturers seemed to re-introduce the infection, while other updates eventually removed it. Notably, 13 Android apps found in Google Play Store carried the same ad-fraud code linking to the Midnight Mimosa network.

The problem here is not a single rogue app but a firmware choreographing multiple parts of the phone. Because the payload runs with elevated privileges, standard uninstall steps often won’t remove it. It can also switch off Google Play Protect temporarily to finish installing itself, then re-enable the Play Store to avoid immediate detection.

For everyday users, the takeaway is a reminder to be cautious with budget phones, especially those using MediaTek chips. If a device shows signs of infection, unusually aggressive ad behavior, unexpected data usage, or apps that keep returning after removal, consider firmware-level fixes from trusted sources and factory resets with care. In many cases, flashing a clean firmware from a reputable source or returning to a known-good version may be necessary, though results vary by model.

01

Which devices are affected

The campaign targets lower-cost Android phones built on MediaTek platforms and includes devices that mimic popular brands. Examples appearing in user reports include models resembling well-known phones, alongside Doogee and Cubot devices. The infections have been reported across more than 150 countries, but a precise, official list of affected models has not been published.

Graphic depiction of a malware icon inside a smartphone
02

How the malware operates

The core component runs with system-level privileges, enabling app installation and removal, permission grants, and code execution from remote servers. A separate module acts as a proxy to forward traffic through the owner’s device, which can support ad fraud and hide the true source of traffic. Some variants disguise themselves as legitimate apps and mislead the Play Store into thinking they came from official channels.

Crucially, the threat can disable the Google Play Store momentarily to complete stealthy tasks, then re-enable the store to avoid drawing attention. Some of the bundled apps that carry the same fraud code were found in the Google Play Store itself, underscoring how wide the reach could be.

03

What this means for everyday people

For shoppers, this story highlights supply-chain and firmware risks in the budget Android market. A device can look fine on day one but still harbor hidden software that’s hard to remove and can quietly co-opt your data connection for others’ use. Ad fraud and traffic relaying are the most visible risks, but there’s potential for broader misuse of your device’s resources.

Cables and servers in a data center, representing traffic routing
04

What to do now

If you own a budget Android device, stick to official firmware updates and avoid untrusted sources. Watch for unfamiliar apps that keep reappearing after you remove them, and review data usage for sudden spikes. If you suspect infection, resetting to factory defaults or reflashing with a trusted clean firmware can help, but outcomes depend on the device and firmware supplier.

05

What happens next

Security researchers say the full scope and origin of Midnight Mimosa are still under investigation. Expect manufacturers to tighten firmware checks and supply-chain defenses, and for more guidance on safe sourcing of budget devices. Until more details emerge, shoppers should favor phones with transparent security histories and regular, verifiable firmware updates.

06

Quick answers

What is Midnight Mimosa?

A firmware-embedded malware campaign on budget Android phones that can silently install and remove apps and turn devices into proxies for traffic and ads.

Which phones are affected?

Lower-cost Android devices using MediaTek chipsets, including models that imitate familiar brands, with infections reported across more than 150 countries.

What should I do now?

Install updates only from official sources, watch for unfamiliar apps, and consider a factory reset or clean reflashing if you suspect an infection.

You're reading the quick version.